Safety
Nobody holds the keys
StockLane's router never holds your tokens between transactions: each swap pulls your input, routes it, checks the output and pays you in the same transaction. These checks are read live from the contracts.
- …The deployer holds no admin role
The wallet that deployed StockLane has no power over it.
- …The router's admin is the timelock
Only the timelock can change the fee, the price guard or the allowed hooks.
- …Every change waits at least 48 hours
Timelock delay: …. Anyone can see a change coming.
- …The oracle and FeeRouter belong to the timelock
No wallet can swap a price feed or redirect fees.
- …The fee is capped in code
Now …. It can never exceed …, even through the timelock.
- …Swaps are open
The guardian can pause swaps in an emergency; only the timelock can unpause.
What protects each swap
- Full fills only. Every hop must use its whole input, or the swap reverts. Nothing is left behind.
- Canonical pools only. v3 pools must come from the Uniswap factory; v4 pools must be hookless or use a hook the timelock allowed (the Pons hook, for $LANE).
- Chainlink price guard. When both tokens have a fresh Chainlink price, the output may be at most … worse than the input. Outside market hours there is no fresh price, so only your minimum applies.
- Your minimum and deadline. You sign the least you accept and a 10-minute deadline.
Contracts
| LaneRouter | 0x56d8…9BDB |
| Timelock (48h) | 0xbe4E…8eF8 |
| LaneOracle | 0x010f…af29 |
| FeeRouter | 0x5f7F…E22c |
| DrawdownRetire | 0xaEc6…B56D |
| Burn adapter | 0xD971…9D30 |
| Admin (proposes to the timelock) | 0x9ef9…0587 |
| Guardian (pause only) | 0xB564…877E |
| Keeper (runs the burn) | 0x53F7…a287 |
Source code and the full verification script: GitHub. Anyone can run ./verify.sh against the live contracts.